PT-2019-5543 · Suse · Opensuse Leap 15.1+6

Malte Kraus

·

Publicado

2019-01-21

·

Atualizado

2024-06-15

·

CVE-2019-3681

CVSS v2.0

10

Crítica

VetorAV:N/AC:L/Au:N/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions SUSE Linux Enterprise Module for Development Tools 15 osc versions prior to 0.169.1-3.20.1 SUSE Linux Enterprise Software Development Kit 12-SP5 osc versions prior to 0.162.1-15.9.1 SUSE Linux Enterprise Software Development Kit 12-SP4 osc versions prior to 0.162.1-15.9.1 openSUSE Leap 15.1 osc versions prior to 0.169.1-lp151.2.15.1 openSUSE Factory osc versions prior to 0.169.0
Description A External Control of File Name or Path vulnerability in osc of SUSE Linux Enterprise Module for Development Tools 15, SUSE Linux Enterprise Software Development Kit 12-SP5, SUSE Linux Enterprise Software Development Kit 12-SP4, openSUSE Leap 15.1, and openSUSE Factory allowed remote attackers that can change downloaded packages to overwrite arbitrary files. This issue is related to incorrect external control of file name or path, which may allow a remote attacker to elevate their privileges.
Recommendations For SUSE Linux Enterprise Module for Development Tools 15 osc versions prior to 0.169.1-3.20.1, update to version 0.169.1-3.20.1 or later. For SUSE Linux Enterprise Software Development Kit 12-SP5 osc versions prior to 0.162.1-15.9.1, update to version 0.162.1-15.9.1 or later. For SUSE Linux Enterprise Software Development Kit 12-SP4 osc versions prior to 0.162.1-15.9.1, update to version 0.162.1-15.9.1 or later. For openSUSE Leap 15.1 osc versions prior to 0.169.1-lp151.2.15.1, update to version 0.169.1-lp151.2.15.1 or later. For openSUSE Factory osc versions prior to 0.169.0, update to version 0.169.0 or later.

Exploit

Correção

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

BDU:2020-04043
CVE-2019-3681
OPENSUSE-SU-2020:0852-1
OPENSUSE-SU-2020_0852-1
OPENSUSE-SU-2024:11133-1
SUSE-SU-2020:1528-1
SUSE-SU-2020:1695-1
SUSE-SU-2020:1695-2
SUSE-SU-2020_1528-1
SUSE-SU-2020_1695-1
SUSE-SU-2020_1695-2
SUSE-SU-2022:4351-1
SUSE-SU-2022_4351-1

Produtos afetados

Suse Linux Enterprise Module For Development Tools 15
Suse Linux Enterprise Software Development Kit 12-Sp4
Suse Linux Enterprise Software Development Kit 12-Sp5
Suse
Opensuse Factory
Opensuse Leap 15.1
Osc